CVE-2026-70426: Critical Jenkins RCE Flaw Bypasses Deserialization Filter
ID: 026851a8-7a03-53ed-be8b-12f42d26488b
STIX ID: report--026851a8-7a03-53ed-be8b-12f42d26488b
Feed Name: securityonline.info
Threat Score
Jenkins patched a critical deserialization vulnerability (CVE-2026-70426) that bypasses the JEP-200 class filter in Remoting, allowing attackers with Agent/Connect permission to run code on the controller; the advisory fixes this issue and 22 other flaws (including a path traversal, CVE-2026-70428), lists affected weekly and LTS releases, and recommends immediate updates to fixed versions or applying provided workarounds while reviewing agent permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
